Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Mandiant M-Trends — read assessment
  72. Metasploit Documentation — read assessment
  73. Microsoft Azure Security Documentation — read assessment
  74. Microsoft Digital Defense Report — read assessment
  75. Microsoft Entra Documentation — read assessment
  76. Microsoft Sentinel Content Hub — read assessment
  77. Microsoft Threat Intelligence blog — read assessment
  78. MISP — read assessment
  79. MITRE ATLAS — read assessment
  80. MITRE ATT&CK — read assessment
  81. MITRE D3FEND — read assessment
  82. MobSF — read assessment
  83. National Vulnerability Database — read assessment
  84. NCSC AI Security Guidance — read assessment
  85. NCSC Cyber Assessment Framework — read assessment
  86. NCSC Ireland Guidance — read assessment
  87. NCSC UK Guidance — read assessment
  88. NDSS Symposium — read assessment
  89. NIST AI Risk Management Framework — read assessment
  90. NIST Cybersecurity Framework — read assessment
  91. NIST SP 800-207 Zero Trust Architecture — read assessment
  92. NIST SP 800-53 — read assessment
  93. NIST SP 800-61 Rev. 3 — read assessment
  94. Nmap Documentation — read assessment
  95. OASIS Open CTI Documentation — read assessment
  96. Open Source Vulnerabilities — read assessment
  97. OpenCTI — read assessment
  98. OpenSecurityTraining2 — read assessment
  99. OpenSSF — read assessment
  100. OSINT Framework — read assessment
  101. OSS-Fuzz — read assessment
  102. OverTheWire — read assessment
  103. OWASP API Security Project — read assessment
  104. OWASP ASVS — read assessment
  105. OWASP Cheat Sheet Series — read assessment
  106. OWASP GenAI Security Project — read assessment
  107. OWASP MASTG — read assessment
  108. OWASP MASVS — read assessment
  109. OWASP Top 10 — read assessment
  110. OWASP Web Security Testing Guide — read assessment
  111. PayloadsAllTheThings — read assessment
  112. PentesterLab — read assessment
  113. PingCastle — read assessment
  114. Plaso — read assessment
  115. PortSwigger Research — read assessment
  116. PortSwigger Web Security Academy — read assessment
  117. Promptfoo — read assessment
  118. Prowler — read assessment
  119. Purple Knight — read assessment
  120. pwntools — read assessment
  121. PyRIT — read assessment
  122. Rapid7 Vulnerability & Exploit Database — read assessment
  123. Recorded Future Triage — read assessment
  124. Red Canary Threat Detection Report — read assessment
  125. REMnux — read assessment
  126. ROP Emporium — read assessment
  127. SANS Internet Storm Center — read assessment
  128. Security Onion — read assessment
  129. Semgrep — read assessment
  130. SentinelOne Labs — read assessment
  131. Shodan — read assessment
  132. Sigma — read assessment
  133. Sigstore — read assessment
  134. SLSA — read assessment
  135. Snort — read assessment
  136. SpecterOps Research — read assessment
  137. SpiderFoot — read assessment
  138. Splunk Security Content — read assessment
  139. Stratosphere IPS Datasets — read assessment
  140. Stratus Red Team — read assessment
  141. Suricata — read assessment
  142. The DFIR Report — read assessment
  143. The Sleuth Kit — read assessment
  144. theHarvester — read assessment
  145. ThreatFox — read assessment
  146. Timesketch — read assessment
  147. Trace Labs — read assessment
  148. Trivy — read assessment
  149. TryHackMe — read assessment
  150. UNB CIC Datasets — read assessment
  151. Unit 42 — read assessment
  152. URLhaus — read assessment
  153. USENIX Security Symposium — read assessment
  154. Velociraptor — read assessment
  155. Verizon Data Breach Investigations Report — read assessment
  156. VirusTotal — read assessment
  157. Volatility Foundation — read assessment
  158. VulnCheck KEV — read assessment
  159. VX-Underground — read assessment
  160. Wazuh — read assessment
  161. Wireshark — read assessment
  162. x64dbg — read assessment
  163. YARA — read assessment
  164. Zeek — read assessment
  165. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

DFIR

1 source

DFIRAssessment tier A

Eric Zimmerman Tools / KAPE

Eric Zimmerman and Kroll

Visit source : Eric Zimmerman Tools / KAPE

Eric Zimmerman's forensic utilities and Kroll Artifact Parser and Extractor form a widely used Windows DFIR collection and parsing workflow. EZ Tools parse artifacts such as event logs, Registry data, prefetch, Amcache, and file-system metadata; KAPE rapidly collects targeted evidence and runs modules against it. They support fast triage and timeline creation, but parser output still requires artifact-specific interpretation and cross-validation. KAPE is governed by Kroll's current license, whose permitted uses and restrictions should be reviewed before deployment or paid third-party work.

Source type
Mixed License Tool
Access
Freemium
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Eric Zimmerman's portable Windows forensic utilities and Kroll Artifact Parser and Extractor support rapid collection, parsing, and review of high-value endpoint artifacts. The EZ Tools family includes focused parsers for event logs, Registry hives, prefetch, Amcache, LNK and Jump List data, Master File Table records, and other Windows evidence. KAPE uses configurable Targets to collect selected artifacts and Modules to process them, allowing responders to acquire useful evidence before a full disk image is available. Analysts can preserve a source, run versioned tools, export structured results, and correlate multiple artifact families into a defensible timeline. Speed does not remove forensic interpretation: timestamps have different meanings, artifacts can be absent or cleaned, collection choices can omit context, and parser versions can change output. Validate high-impact conclusions against the original evidence and a second artifact or tool, record hashes and time-zone handling, and protect collected data as sensitive case material. EZ Tools and KAPE do not share one license. Review each tool's terms, and consult Kroll's current KAPE agreement before organizational use, redistribution, or any paid engagement involving a third-party environment.

Strengths

  • Provides focused, widely used parsers for high-value Windows forensic artifacts
  • KAPE enables fast, configurable evidence collection and automated processing at scale
  • Structured exports support repeatable triage, timelines, and cross-artifact correlation

Limitations

  • Collection targets and parser output can omit context and require artifact-specific validation
  • Licensing differs across the tool collection, and KAPE restrictions must be reviewed for the intended use

Best for

  • Windows endpoint triage
  • Forensic artifact parsing
  • Rapid evidence collection
  • Incident timeline development

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 4/5

Provides focused, widely used parsers for high-value Windows forensic artifacts; principal limitation: Collection targets and parser output can omit context and require artifact-specific validation.

Audience

  • DFIR analysts
  • incident responders
  • forensic examiners
  • threat hunters
  • security consultants

Formats

  • command-line tools
  • tool collection
  • documentation
  • reference material
  • training videos

Keywords

  • dfir
  • windows
  • artifact-parsing
  • forensic-artifacts
  • evidence-collection
  • forensic-timeline
  • incident-response
  • forensic-automation

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Malware Analysis

1 source

Malware AnalysisAssessment tier A

capa

Mandiant FLARE team, Google

Visit source : capa

capa is the FLARE team's open-source capability-identification tool for executable files and supported sandbox reports. Its explainable YAML rules describe behaviors such as persistence, communication, encryption, and process manipulation and can map findings to MITRE ATT&CK and the Malware Behavior Catalog. It accelerates malware triage and guides reverse engineering, but a rule match is evidence of recognized features, not proof that a capability executed or that a file is malicious. Packed, obfuscated, unsupported, or novel code can produce incomplete results and requires analyst validation.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

capa is an open-source FLARE-team tool maintained under Mandiant and Google that identifies program capabilities using a transparent, community-maintained rule set. It analyzes supported PE, ELF, .NET, shellcode, and selected dynamic-analysis report formats, then reports behaviors such as service installation, process creation, cryptography, communication, or anti-analysis. Rule metadata can connect results to MITRE ATT&CK and the Malware Behavior Catalog, and verbose output shows the features and locations that caused a match. Analysts can use capa early in triage to prioritize functions, compare samples, guide work in Ghidra or IDA, and develop reusable rules; the browser-based capa Explorer can inspect result documents interactively. Treat every result as an analytical hypothesis. Static extraction can miss packed, obfuscated, dynamically resolved, or unsupported behavior, while generic library code can create context that looks more important than it is. Dynamic reports inherit the sandbox's visibility and execution path. Preserve the tool and rule versions, review match evidence, combine results with strings, disassembly, telemetry, and sandbox observations, and handle unknown samples only in an authorized isolated analysis environment.

Strengths

  • Uses transparent rules and explainable feature matches to identify program capabilities
  • Supports static binaries and selected dynamic-analysis reports with ATT&CK and MBC mappings
  • Accelerates triage while directing analysts to relevant functions and behaviors

Limitations

  • Packed, obfuscated, unsupported, or novel code can cause incomplete or misleading results
  • A capability match does not prove malicious intent, execution, or case relevance

Best for

  • Malware capability triage
  • Reverse-engineering prioritization
  • Capability-rule development
  • Comparing related executable samples

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Uses transparent rules and explainable feature matches to identify program capabilities; principal limitation: Packed, obfuscated, unsupported, or novel code can cause incomplete or misleading results.

Audience

  • malware analysts
  • reverse engineers
  • incident responders
  • detection engineers
  • security researchers

Formats

  • command-line tool
  • rules
  • json data
  • web interfaces
  • technical documentation

Keywords

  • malware-analysis
  • reverse-engineering
  • binary-analysis
  • static-analysis
  • dynamic-analysis
  • mitre-attack
  • malware-taxonomy
  • rule-authoring

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

SOC

1 source

SOCAssessment tier A

Wazuh

Wazuh, Inc.

Visit source : Wazuh

Wazuh is an open-source security platform that combines endpoint agents, log analysis, file-integrity monitoring, configuration assessment, vulnerability detection, dashboards, and active-response capabilities. Its documentation provides deployable guidance for building a self-managed SIEM and XDR-style environment across endpoints, cloud workloads, and containers. Wazuh can centralize useful telemetry and compliance evidence, but installation alone does not create complete detection coverage. Asset inventory, parsing, rule quality, privileges, retention, tuning, upgrades, and response safeguards determine whether findings are reliable and operationally safe.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Wazuh is an open-source security platform for collecting endpoint and workload telemetry and applying log analysis, file-integrity monitoring, security-configuration assessment, vulnerability detection, threat-detection rules, dashboards, and optional active response. Its agents inventory installed software and system state, while server components correlate events and vulnerability intelligence and expose findings through indexed search and visual interfaces. Security teams can use the official documentation to deploy a lab or production cluster, onboard endpoints, tune decoders and rules, map alerts to MITRE ATT&CK, and integrate external intelligence or automation. It is useful for organizations seeking a self-managed monitoring stack, but its broad feature set creates operational responsibility. Vulnerability matches depend on inventory and version correlation; file changes are not inherently malicious; and default rules can create both noise and blind spots. Engineers must secure agents, enrollment keys, management services, indices, credentials, and response actions, while monitoring ingestion health, storage, and upgrade compatibility. Establish local detection hypotheses, validate alerts against raw events and endpoint evidence, test active-response logic safely, and measure collection and rule coverage rather than equating deployment with effective SIEM, endpoint detection, or compliance.

Strengths

  • Integrates endpoint inventory, log analysis, file integrity, vulnerability detection, and dashboards
  • Offers extensive open documentation and configurable rules for self-managed security operations
  • Supports heterogeneous endpoints, cloud workloads, containers, and compliance-oriented monitoring

Limitations

  • Requires sustained engineering for sizing, ingestion, tuning, upgrades, access control, and retention
  • Default correlations and vulnerability matches require local validation and do not guarantee detection coverage

Best for

  • Self-managed security monitoring
  • Endpoint log and integrity analysis
  • Vulnerability and configuration visibility
  • SOC platform engineering

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Integrates endpoint inventory, log analysis, file integrity, vulnerability detection, and dashboards; principal limitation: Requires sustained engineering for sizing, ingestion, tuning, upgrades, access control, and retention.

Audience

  • SOC analysts
  • security platform engineers
  • system administrators
  • detection engineers
  • compliance teams

Formats

  • open-source software
  • technical documentation
  • rules
  • web interfaces
  • api documentation

Keywords

  • soc
  • siem
  • endpoint-telemetry
  • log-analysis
  • file-system-analysis
  • vulnerability-management
  • configuration-audit
  • security-automation

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Supply Chain Security

3 sources

Supply Chain SecurityAssessment tier A

OpenSSF

Open Source Security Foundation, Linux Foundation

Visit source : OpenSSF

The Open Source Security Foundation coordinates cross-industry work to improve open-source software security. Its project and guidance portfolio includes Scorecard, Best Practices Badge, SLSA, Sigstore, GUAC, OSPS Baseline, vulnerability-disclosure work, secure-development education, and other technical initiatives. It is a valuable map of community standards, tools, and implementation resources for maintainers and consumers. Project maturity and scope vary, automated scores are risk signals rather than guarantees, and foundation guidance must be translated into a threat-informed program with evidence from the software and environment being assessed.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Open Source Security Foundation is a Linux Foundation community that coordinates developers, security engineers, vendors, researchers, and public-sector stakeholders around securing open-source software. Its technical initiatives and working groups cover developer best practices, repository security, vulnerability disclosure, fuzzing, software bills of materials, supply-chain integrity, education, and policy. The project directory provides first-party entry points to resources such as Scorecard, Best Practices Badge, SLSA, Sigstore, GUAC, OSPS Baseline, and OSV Schema. Maintainers can use the guidance to improve repository controls and disclosure processes; platform teams can evaluate supply-chain tools; and consumers can use project metadata and automated checks as inputs to dependency governance. Treat OpenSSF as a coordination and implementation ecosystem, not a single certification authority. Hosted initiatives have different lifecycle stages, maintainers, release cadences, threat models, and adoption requirements. Scorecard checks and badges reveal documented practices or observable signals but do not prove that a dependency is safe. Verify the maturity and current documentation of each project, preserve tool versions and evidence, and combine foundation resources with code review, vulnerability intelligence, operational testing, supplier context, and accountable risk decisions.

Strengths

  • Coordinates a broad, vendor-neutral portfolio of open-source security projects and guidance
  • Connects maintainers and consumers to practical tools, standards, education, and policy work
  • Publishes transparent project governance and lifecycle information through an open community

Limitations

  • Hosted projects differ in maturity, scope, maintenance, and operational adoption
  • Automated scores, badges, and guidance are inputs to assurance rather than guarantees of software safety

Best for

  • Open-source security program design
  • Repository and dependency governance
  • Supply-chain tool discovery
  • Maintainer security improvement

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 4.5/5

Coordinates a broad, vendor-neutral portfolio of open-source security projects and guidance; principal limitation: Hosted projects differ in maturity, scope, maintenance, and operational adoption.

Audience

  • open-source maintainers
  • software security teams
  • DevSecOps engineers
  • security architects
  • policy professionals

Formats

  • project documentation
  • best-practice guides
  • standards
  • training materials
  • open-source tools

Keywords

  • open-source-security
  • supply-chain-security
  • secure-development
  • dependency-security
  • governance
  • devsecops
  • community
  • standards

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Supply Chain SecurityAssessment tier A

SLSA

Open Source Security Foundation

Visit source : SLSA

SLSA is an OpenSSF specification for incrementally improving software supply-chain integrity through defined tracks, assurance levels, and machine-verifiable attestations such as build provenance. It gives producers, build platforms, and consumers a shared way to describe how source and artifacts were created and protected. SLSA is valuable for CI/CD architecture and supplier assurance, but conformance does not prove that source code is benign, vulnerability-free, or fit for purpose. Record the specification version and verify attestations against an explicit trust policy rather than treating a badge as sufficient evidence.

Source type
Standards Body
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

SLSA is an industry-consensus specification maintained by the Open Source Security Foundation for describing and incrementally improving software supply-chain security. The specification organizes requirements into tracks and levels and defines recommended attestation formats, including build provenance, so producers can make verifiable claims about how an artifact was built and consumers can evaluate those claims. Platform and DevSecOps teams can use SLSA to threat-model source and build workflows, select an attainable assurance level, configure hosted or isolated builders, emit provenance, and enforce verification before release or deployment. Procurement and risk teams can also use it as a structured language for supplier questions. Always record the exact SLSA version and track because requirements evolve between revisions. A valid attestation only supports the claims it contains and remains dependent on builder identity, trust roots, policy, and verifier behavior. SLSA does not establish that reviewed source is safe, that dependencies lack vulnerabilities, or that the resulting program behaves securely. Combine it with code review, dependency and vulnerability controls, protected identities, reproducible evidence where appropriate, and tested consumer-side verification rather than relying on provenance generation alone.

Strengths

  • Provides a vendor-neutral vocabulary of tracks and levels for software supply-chain assurance
  • Defines machine-verifiable provenance and other attestations for producers and consumers
  • Supports incremental adoption across build platforms, CI/CD pipelines, and supplier requirements

Limitations

  • Conformance and provenance do not prove that source code or dependencies are secure
  • Requirements vary by specification version, track, trust model, and consumer verification policy

Best for

  • Build-pipeline threat modeling
  • Software provenance requirements
  • CI/CD assurance roadmaps
  • Supplier security assessment

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Provides a vendor-neutral vocabulary of tracks and levels for software supply-chain assurance; principal limitation: Conformance and provenance do not prove that source code or dependencies are secure.

Audience

  • DevSecOps engineers
  • software maintainers
  • platform engineers
  • security architects
  • supplier assurance teams

Formats

  • standard specification
  • framework
  • implementation guidance
  • schemas
  • technical documentation

Keywords

  • supply-chain-security
  • ci-cd
  • devsecops
  • assurance
  • supplier-assurance
  • standards
  • machine-readable-data
  • trust-analysis

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Supply Chain SecurityAssessment tier A

Sigstore

Open Source Security Foundation

Visit source : Sigstore

Sigstore is an open-source framework for signing and verifying software artifacts with tools and services including Cosign, Fulcio, Rekor, and a distributed trust root. Its identity-based workflow can bind a short-lived certificate to an OIDC identity and record signing evidence in a transparency log, reducing long-lived key-management burden. It supports containers, binaries, release files, SBOMs, and attestations. A valid signature proves only the defined identity and artifact relationship; consumers still need trusted identity expectations, log and certificate verification, policy enforcement, and independent security evaluation.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Sigstore is an OpenSSF-hosted open-source ecosystem for signing, recording, and verifying software artifacts. Cosign signs containers, files, and attestations; Fulcio issues short-lived certificates tied to supported OpenID Connect identities; Rekor records signing metadata in an append-only transparency log; and the Sigstore trust root distributes material needed to validate the services. Maintainers can integrate identity-based signing into CI, publish verification bundles alongside releases, and record provenance or SBOM attestations. Consumers can require expected issuer and identity values, verify artifact digests and signatures, and check transparency-log inclusion before accepting a release. The workflow reduces long-lived private-key handling, but it introduces a trust model that must be understood and monitored. A compromised identity or workflow may still produce a cryptographically valid signature, public logs expose signing metadata, and private or offline environments may require custom deployment choices. Signing does not establish code quality, benign behavior, vulnerability status, or authorization to deploy. Pin and review verification policy, protect CI identities and permissions, monitor unexpected signing events, retain verifiable bundles, plan trust-root updates, and test failure behavior at the actual artifact-consumption point.

Strengths

  • Provides integrated open tooling for artifact signing, identity binding, transparency, and verification
  • Short-lived certificates reduce dependence on long-lived developer signing keys
  • Supports automated CI workflows and multiple artifact and attestation formats

Limitations

  • A valid signature does not prove that software is safe, reviewed, or authorized for deployment
  • OIDC identity, transparency, trust-root, privacy, and consumer-policy assumptions require explicit management

Best for

  • Software release signing
  • Container and artifact verification
  • CI/CD identity-based signing
  • Attestation transparency

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Provides integrated open tooling for artifact signing, identity binding, transparency, and verification; principal limitation: A valid signature does not prove that software is safe, reviewed, or authorized for deployment.

Audience

  • software maintainers
  • DevSecOps engineers
  • platform engineers
  • software consumers
  • security architects

Formats

  • open-source tooling
  • command-line tool
  • technical documentation
  • api documentation
  • structured data

Keywords

  • supply-chain-security
  • open-source-security
  • ci-cd
  • devsecops
  • authentication
  • trust-analysis
  • software-composition-analysis
  • machine-readable-data

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Reports

1 source

Category

Vulnerability

1 source

VulnerabilityAssessment tier A

VulnCheck KEV

VulnCheck

Visit source : VulnCheck KEV

VulnCheck KEV is a vendor-maintained catalog of vulnerabilities assessed as exploited in the wild, with evidence references and additional exploit context. It can broaden and accelerate prioritization beyond CISA KEV and supports enrichment through VulnCheck's community and product interfaces. Community access currently requires registration, and comparative coverage claims come from the vendor. Treat each record as an evidence-backed prioritization signal rather than proof that an asset is exposed or compromised, and verify the cited evidence, affected versions, remediation, and local business impact before action.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

VulnCheck KEV is a continuously maintained commercial-provider catalog of CVEs for which VulnCheck has identified evidence of exploitation in the wild. The service adds citations, external exploit references, and links to publicly available proof-of-concept context, and VulnCheck positions it as broader and earlier than other public known-exploitation catalogs. Vulnerability teams can use it as a second exploitation signal alongside CISA KEV, enrich asset records, find evidence that supports escalation, and identify issues that deserve rapid vendor-advisory review. Registered Community members currently receive no-cost access, while additional delivery and intelligence capabilities are part of VulnCheck's commercial offering; confirm the current access and attribution terms before automating use. The catalog's inclusion methodology, measurements, and coverage comparisons are vendor-defined, and referenced evidence or code can change or disappear. A listed CVE does not establish that a particular version is deployed, reachable, exploitable under local conditions, or compromised. Follow every high-priority item to its evidence and current vendor bulletin, match it to reliable inventory, and combine exploitation status with exposure, controls, business criticality, patch feasibility, and incident evidence. Do not equate absence from VulnCheck KEV with absence of exploitation.

Strengths

  • Adds evidence-linked known-exploitation coverage beyond a single government catalog
  • Provides exploit references and operational context for vulnerability prioritization
  • Supports rapid enrichment of asset, ticketing, and vulnerability-management workflows

Limitations

  • Community access requires registration, and advanced delivery or intelligence capabilities may be commercial
  • Inclusion criteria and comparative coverage claims are vendor-defined and require evidence review

Best for

  • Risk-based vulnerability prioritization
  • Known-exploitation cross-checking
  • Vulnerability intelligence enrichment
  • Early-warning patch triage

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Adds evidence-linked known-exploitation coverage beyond a single government catalog; principal limitation: Community access requires registration, and advanced delivery or intelligence capabilities may be commercial.

Audience

  • vulnerability managers
  • security operations teams
  • incident responders
  • risk owners
  • security engineers

Formats

  • searchable catalog
  • api
  • json data
  • vulnerability records
  • reference links

Keywords

  • known-exploited-vulnerabilities
  • vulnerability-management
  • active-exploitation
  • patch-prioritization
  • indicator-enrichment
  • proof-of-concept
  • cve
  • commercial

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.